Regimly

Legal

Privacy Policy

Effective date: September 6, 2026 · Applies to Regimly v0.8+ · Operated by Svetlana Chrysler (sole proprietor) · Contact: privacy@regimly.com

Regimly (“we”, “us”) is a skincare organization and education app. This policy explains what we process, why, where it lives, and the choices you have. It reflects the app as actually built — every statement below was verified against the application source code and live backend configuration on the effective date.

1. What we process

2. Where your data lives

3. AI processing (Google Vertex AI — Gemini)

Product identification, routine generation, Remi’s answers and the alternatives feature run on Google Cloud Vertex AI (Gemini models), always through our backend — the app holds no AI credentials. Depending on the feature, the AI receives: product or ingredient-label photos, your product list, skin type, concerns, age range, and your chat messages, in your chosen language.

What the AI never receives: your name, email, exact age, user ID, or face photos. Per Google Cloud’s Vertex AI terms, customer inputs and outputs are not used to train Google’s models; processing is transient in the EU region we selected. We do not store raw AI requests; results you choose to keep (an identified product, a generated routine) are saved to your profile.

4. Why we process it

5. Who receives data

6. Retention & deletion

7. Security

All traffic uses HTTPS/TLS. Cloud data is encrypted at rest. Database and file access is restricted per-user by security rules keyed to your authenticated ID; backend AI calls authenticate with a service account, never an embedded key. Production access is limited to the project owner.

8. International transfers

Your profile, database records and all AI processing stay in the European Union. Product photos are stored in the United States (Google Cloud Storage, us-central1). For EU/EEA users this transfer relies on Google Cloud’s Standard Contractual Clauses and Google LLC’s certification under the EU–U.S. Data Privacy Framework.

9. Analytics & your choices

Analytics is opt-in. The app asks once, on first use, and collects nothing until you agree. You can change your choice at any time in the app: Profile tab → Anonymous usage stats. Advertising ID collection is disabled. Crash reporting runs only in release builds.

10. Age

Regimly is for ages 14 and over. Onboarding requires choosing an age range; choosing “Under 14” ends the session and immediately deletes the just-created account — no profile is stored. Please note the age control is enforced in the app based on the user’s own answer.

11. Your rights

Depending on your law (GDPR, CCPA and others), you may have rights to access, correct, delete, restrict, object, and port your data, and to withdraw consent. Most of these you can exercise directly: everything we hold about you is visible in the app, editable there (Profile tab), and deletable via either deletion route. For anything else: privacy@regimly.com. You may also complain to your local supervisory authority.